TF-MAL-apk.elibomi
📛 Threat Title
Malware family: Elibomi
Description
ThreatFox malware family `apk.elibomi`. Printable name: Elibomi. Aliases: Drinik.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.elibomi
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.elibomi
IOC database
- Type
- domain
- Value
apk.elibomi- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.elibomi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.elibomi
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:dl.acm.org
In response, Artificial Intelligence (AI) models are increasingly leveraged to enhance malware classification and remediation efforts. However, while such models trained to classify malware datasets often perform well in controlled environments, research increasingly shows that conventional AI-based malware classifiers struggle to generalize to ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Elibomi malware family including references, samples and yara signatures.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.enigmasoftware.com
A new family of phishing Android malware has been spotted being used in live attacks by cybercriminals. The threat was discovered by the researchers who named it Elibomi . The threat relies on social engineering tactics and fake Android applications to collect information from its victims and exfiltrate it to servers under the control of the hackers. First Elibomi Attack The first attack ...
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
Elibomi malware overview As mentioned in the introduction, there are several versions of Elibomi . The latest variants employ the Android Accessibility Services to gain access and control over compromised devices. Cyber criminals may gain near-user-level control of the system by abusing these services.
-
web:www.sciencedirect.com
It is essential to do malware detection analyses since malware is becoming more sophisticated and prevalent. Numerous researchers work to counteract Android malware intrusions in different ways. Malware detection and classification work best with large datasets that contain all current malware types.
-
web:www.trendmicro.com
As of this writing, we observed five banking malware families involved in these attacks, namely Elibomi , FakeReward, AxBanker, IcRAT, and IcSpy. We analyzed that the bank customers targeted include account subscribers of seven banks, including some of the most well-known banks located in the country and potentially affecting millions of customers.
-
web:zimperium.com
Elibomi is Android malware actively targeting users, particularly in India, by masquerading as legitimate applications to steal sensitive personal and financial information. Its evolution and sophisticated techniques underscore the critical importance of mobile app security for developers and organizations, especially those in the enterprise sector.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.